View Single Post
Old 01-19-2006, 11:36 AM   #41 (permalink)
stretched
Registered User
 
Join Date: Aug 2005
Posts: 115
OS: Windows XP


Having troubles logging in here with this account, keeps making me put my password with every page and I am selecting remember me....

This is user account: "manny"

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 11:31:40 AM, 1/19/2006
+ Report-Checksum: 1A39040

+ Scan result:

HKLM\SOFTWARE\Toolbar -> Spyware.WebSearch : Error during cleaning
HKLM\SOFTWARE\Toolbar\Downloads -> Spyware.WebSearch : Error during cleaning
HKLM\SOFTWARE\Toolbar\Files -> Spyware.WebSearch : Error during cleaning
HKLM\SOFTWARE\Toolbar\Install -> Spyware.WebSearch : Error during cleaning
HKLM\SOFTWARE\Toolbar\PlugIns -> Spyware.WebSearch : Error during cleaning
HKLM\SOFTWARE\Toolbar\Server -> Spyware.WebSearch : Error during cleaning


::Report End

Webroot Spysweeper LOG

********
11:35 AM: | Start of Session, Thursday, January 19, 2006 |
11:35 AM: Spy Sweeper started
11:35 AM: Sweep initiated using definitions version 602
11:35 AM: Starting Memory Sweep
11:38 AM: Memory Sweep Complete, Elapsed Time: 00:03:20
11:38 AM: Starting Registry Sweep
11:38 AM: Found Adware: websearch toolbar
11:38 AM: HKLM\software\toolbar\ (6 subtraces) (ID = 646240)
11:39 AM: HKU\WRSS_Profile_S-1-5-21-2034715575-3859179852-3284876818-1006\software\toolbar\ (2 subtraces) (ID = 146513)
11:39 AM: HKU\WRSS_Profile_S-1-5-21-2034715575-3859179852-3284876818-1006\software\toolbar\ (2 subtraces) (ID = 646239)
11:39 AM: Registry Sweep Complete, Elapsed Time:00:01:05
11:39 AM: Starting Cookie Sweep
11:39 AM: Found Spy Cookie: pointroll cookie
11:39 AM: hehehe@ads.pointroll[1].txt (ID = 3148)
11:39 AM: Found Spy Cookie: advertising cookie
11:39 AM: hehehe@advertising[1].txt (ID = 2175)
11:39 AM: Found Spy Cookie: ask cookie
11:39 AM: hehehe@ask[1].txt (ID = 2245)
11:39 AM: Found Spy Cookie: atlas dmt cookie
11:39 AM: hehehe@atdmt[2].txt (ID = 2253)
11:39 AM: Found Spy Cookie: centrport net cookie
11:39 AM: hehehe@centrport[1].txt (ID = 2374)
11:39 AM: Found Spy Cookie: questionmarket cookie
11:39 AM: hehehe@questionmarket[1].txt (ID = 3217)
11:39 AM: Found Spy Cookie: tribalfusion cookie
11:39 AM: hehehe@tribalfusion[1].txt (ID = 3589)
11:39 AM: zakariya@ads.pointroll[2].txt (ID = 3148)
11:39 AM: zakariya@atdmt[1].txt (ID = 2253)
11:39 AM: zakariya@centrport[1].txt (ID = 2374)
11:39 AM: zakariya@tribalfusion[2].txt (ID = 3589)
11:39 AM: Cookie Sweep Complete, Elapsed Time: 00:00:08
11:39 AM: Starting File Sweep
12:12 PM: File Sweep Complete, Elapsed Time: 00:33:09
12:13 PM: Full Sweep has completed. Elapsed time 00:37:54
12:13 PM: Traces Found: 24
12:17 PM: Removal process initiated
12:17 PM: Quarantining All Traces: websearch toolbar
12:17 PM: websearch toolbar is in use. It will be removed on reboot.
12:17 PM: HKLM: software\toolbar\ is in use. It will be removed on reboot.
12:17 PM: Quarantining All Traces: advertising cookie
12:17 PM: Quarantining All Traces: ask cookie
12:17 PM: Quarantining All Traces: atlas dmt cookie
12:17 PM: Quarantining All Traces: centrport net cookie
12:17 PM: Quarantining All Traces: pointroll cookie
12:17 PM: Quarantining All Traces: questionmarket cookie
12:17 PM: Quarantining All Traces: tribalfusion cookie
12:17 PM: Removal process completed. Elapsed time 00:00:19
********
12:49 PM: | Start of Session, Tuesday, January 17, 2006 |
12:49 PM: Spy Sweeper started
12:49 PM: Sweep initiated using definitions version 602
12:49 PM: Starting Memory Sweep
12:52 PM: Memory Sweep Complete, Elapsed Time: 00:02:58
12:52 PM: Starting Registry Sweep
12:53 PM: Found Adware: websearch toolbar
12:53 PM: HKLM\software\toolbar\ (6 subtraces) (ID = 646240)
12:53 PM: HKU\WRSS_Profile_S-1-5-21-2034715575-3859179852-3284876818-1006\software\toolbar\ (2 subtraces) (ID = 146513)
12:53 PM: HKU\WRSS_Profile_S-1-5-21-2034715575-3859179852-3284876818-1006\software\toolbar\ (2 subtraces) (ID = 646239)
12:53 PM: Registry Sweep Complete, Elapsed Time:00:01:04
12:53 PM: Starting Cookie Sweep
12:53 PM: Cookie Sweep Complete, Elapsed Time: 00:00:07
12:54 PM: Starting File Sweep
1:30 PM: File Sweep Complete, Elapsed Time: 00:36:18
1:30 PM: Full Sweep has completed. Elapsed time 00:40:36
1:30 PM: Traces Found: 13
1:33 PM: Removal process initiated
1:34 PM: Quarantining All Traces: websearch toolbar
1:34 PM: websearch toolbar is in use. It will be removed on reboot.
1:34 PM: HKLM: software\toolbar\ is in use. It will be removed on reboot.
1:34 PM: Removal process completed. Elapsed time 00:00:21
1:47 PM: IE Security Shield: found: C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE -- IE Security modification allowed at user request
11:34 AM: Warning: Failed to register registry notification for "HKLM\Software\Microsoft\Windows\CurrentVersion\Run": Access is denied
11:35 AM: | End of Session, Thursday, January 19, 2006 |
********
12:47 PM: | Start of Session, Tuesday, January 17, 2006 |
12:47 PM: Spy Sweeper started
12:48 PM: Warning: Failed to register registry notification for "HKLM\Software\Microsoft\Windows\CurrentVersion\Run": Access is denied
12:49 PM: | End of Session, Tuesday, January 17, 2006 |
****************************************

Logfile of HijackThis v1.99.1
Scan saved at 12:20:01 PM, on 1/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.activision.com/spider-man
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: X1IEHook Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/k...an_unicode.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


YES that last post was about rocky account, and thank you very much for all the toiling...
stretched is offline  
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here